CVE-2026-71845
- EPSS 0.21%
- Veröffentlicht 11.08.2026 19:22:12
- Zuletzt bearbeitet 05.09.2026 18:17:28
A flaw was found in insights-client. The setDefault() function logs the value of every environment variable it processes, including CCX_TOKEN, a bearer credential used in disconnected cluster deployments. When glog verbosity is set to level 2 or high...
- EPSS 0.25%
- Veröffentlicht 05.08.2026 09:18:14
- Zuletzt bearbeitet 08.09.2026 14:17:20
A flaw was found in the Application Subscription controller (multicluster-operators-subscription) of Red Hat Advanced Cluster Management for Kubernetes (ACM). A user with namespace-scoped "edit" privileges in an ACM hub namespace can create a Channel...
CVE-2026-17107
- EPSS 0.35%
- Veröffentlicht 24.07.2026 18:56:05
- Zuletzt bearbeitet 29.09.2026 19:17:25
A flaw was found in the cluster-proxy service-proxy component used in Red Hat Advanced Cluster Management for Kubernetes (RHACM) and multicluster-engine (MCE). The service-proxy appends impersonation group headers to proxied requests without first re...
CVE-2026-44495
- EPSS 0.78%
- Veröffentlicht 11.06.2026 15:33:12
- Zuletzt bearbeitet 11.09.2026 13:18:08
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already po...
CVE-2025-57851
- EPSS 0.11%
- Veröffentlicht 08.04.2026 13:55:00
- Zuletzt bearbeitet 24.07.2026 20:10:00
A container privilege escalation flaw was found in certain Multicluster Engine for Kubernetes images. This issue stems from the /etc/passwd file being created with group-writable permissions during build time. In certain conditions, an attacker who c...
CVE-2026-4740
- EPSS 0.15%
- Veröffentlicht 07.04.2026 14:30:36
- Zuletzt bearbeitet 08.09.2026 12:16:54
A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed cluster administrator to forge a client certificate ...
CVE-2025-14874
- EPSS 0.47%
- Veröffentlicht 18.12.2025 08:40:31
- Zuletzt bearbeitet 07.10.2026 11:10:00
A flaw was found in Nodemailer. This vulnerability allows a denial of service (DoS) via a crafted email address header that triggers infinite recursion in the address parser.
CVE-2025-6017
- EPSS 0.13%
- Veröffentlicht 02.07.2025 06:36:47
- Zuletzt bearbeitet 20.08.2025 16:33:58
A flaw was found in Red Hat Advanced Cluster Management through versions 2.10, before 2.10.7, 2.11, before 2.11.4, and 2.12, before 2.12.4. This vulnerability allows an unprivileged user to view confidential managed cluster credentials through the UI...
CVE-2023-44487
- EPSS 100%
- Veröffentlicht 10.10.2023 14:15:10
- Zuletzt bearbeitet 11.08.2026 19:37:30
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
CVE-2022-3248
- EPSS 0.4%
- Veröffentlicht 05.10.2023 14:15:09
- Zuletzt bearbeitet 21.11.2024 07:19:08
A flaw was found in OpenShift API, as admission checks do not enforce "custom-host" permissions. This issue could allow an attacker to violate the boundaries, as permissions will not be applied.